On 1/22/22 23:16, William ML Leslie wrote:
> On Sun, 23 Jan 2022, 2:44 pm Mike Stay, <
meta...@gmail.com
> <mailto:
meta...@gmail.com>> wrote:
>
>
https://twitter.com/rmondello/status/1484571223250067456
WebAuthn is based on the work of the FIDO Alliance, which was intended
to be a standards-based answer to Apple's TouchID biometric authN. The
Apple implementation is excellent, as is Google's support for things
like Yubikey (USB-based devices). "Passwordless" authentication is now
actually real.
It looks like a decent start, but the question I feel
> I want an answer to is how do I do three-party auth if credentials are
> scoped to a hostname...
Well, in a way, there are already (at least) three parties in the
WebAuthn flow - the user, her browser, and the website (RP). I suppose
there's also the phone/biometric hardware, which must also be
authenticated in this flow. Which three parties are you thinking of?
This blog goes into some detail about WebAuthn on the iPhone, and
discusses what I consider a bit of an annoyance (although this is a
"standard", support isn't standard across software).
https://www.security-embedded.com/blog/2021/5/2/under-the-hood-webauthn-in-safari
- johnk
>
> --
> You received this message because you are subscribed to the Google
> Groups "cap-talk" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to
cap-talk+u...@googlegroups.com
> <mailto:
cap-talk+u...@googlegroups.com>.
> To view this discussion on the web visit
>
https://groups.google.com/d/msgid/cap-talk/CAHgd1hE9RKfz5xJ5AKN1p489LOAcRRpRve0QeP3fP_Xm1R%3DS9g%40mail.gmail.com
> <
https://groups.google.com/d/msgid/cap-talk/CAHgd1hE9RKfz5xJ5AKN1p489LOAcRRpRve0QeP3fP_Xm1R%3DS9g%40mail.gmail.com?utm_medium=email&utm_source=footer>.